CVE-2024-22036
Severity CVSS v4.0:
Pending analysis
Type:
CWE-269
Improper Privilege Management
Publication date:
16/04/2025
Last modified:
15/04/2026
Description
A vulnerability has been identified within Rancher where a cluster or node driver can be used to escape the chroot<br />
jail and gain root access to the Rancher container itself. In <br />
production environments, further privilege escalation is possible based <br />
on living off the land within the Rancher container itself. For the test<br />
and development environments, based on a –privileged Docker container, <br />
it is possible to escape the Docker container and gain execution access <br />
on the host system.<br />
<br />
<br />
This issue affects rancher: from 2.7.0 before 2.7.16, from 2.8.0 before 2.8.9, from 2.9.0 before 2.9.3.
Impact
Base Score 3.x
9.10
Severity 3.x
CRITICAL



